Who Should Use This Hub
Use this hub when your product or enterprise processes personal data of individuals in India — whether you operate in India, or serve Indian customers from the US, the Gulf, Europe, Asia or Australia. The Act applies extraterritorially to processing connected with offering goods or services to people in India.
The mistake many teams make is treating DPDP compliance as a document exercise after the product is designed. Consent flows, privacy notices, retention windows, breach response and governance obligations shape product design, user journeys, data architecture and procurement.
A practical compliance roadmap should connect legal interpretation with operational design. The goal is to know what is in scope, which controls are required, who owns them, how evidence is collected and how the program changes as rules evolve.